
User16355408004815339458 (Customer) asked a question.
Hi,
I'm investigating an macOS app that querying Okta every 15 minutes for OIDC app. at Okta.
It continue to query even user changes account password which gets auth. failure every 15 minutes.
Developer has been failing to provide the cause why it keeps querying Okta even it is not designed to stop on first auth. failure and forward.
Agent's log is like below
2023-12-12 21:50:30.419536+0900 0x438e Error 0x0 312 0 kandji-daemon: [io.kandji.KandjiAgent:Requests] Completed with error POST token: 400 (bad request)
2023-12-12 22:05:29.855770+0900 0x9d92 Error 0x0 312 0 kandji-daemon: [io.kandji.KandjiAgent:Requests] Completed with error POST token: 400 (bad request)
2023-12-12 22:20:29.941488+0900 0xf127 Error 0x0 312 0 kandji-daemon: [io.kandji.KandjiAgent:Requests] Completed with error POST token: 400 (bad request)
And Okta's System Log is like this
Apparently, customer working on other while macOS running, their account gets locked out by this consecutive auth failures. Pretty unacceptable.
As app. developer does not know what to do about it, I could help them by providing exact request Okta got from the agent.
Is there a way to retrieve exact query Okta got on my own?

Hi @User16355408004815339458 (Customer) , Thank you for reaching out to the Okta Community!
If you’ve confirmed that the behavior is consistent, as in - the request is always coming from the same device/IP - you might be able to rule out malicious events.
Assuming that the events are caused by an authentication request triggered by some kind of app on the user’s machine, I would recommend looking into where the user’s credentials are required.
I’ve seen similar behavior when users changed their Okta password but forgot to update it in their Outlook desktop app for example. The Outlook app kept trying to re-authenticate automatically with the old credentials it had stored, causing the user’s account to be locked.
Judging by the log information you’ve provided, I assume the user has some kind of Kandji client installed on their device, which may be trying to automatically re-authenticate, but it’s using the wrong credentials.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--------------------------------
Ask the Experts: Okta Device Access Product Team Now Thru 3/22